So many people are getting the SHA1 story wrong. With the collision that Google released, *anyone* can create colliding PDFs for *free*.
-
-
Replying to @marcan42
You can take the two sets of 320 bytes that were published, append *anything* to both sets, and they will still have the same hash.
6 replies 105 retweets 105 likes -
Replying to @andrewgdotcom @thegrugq
You could have one document digitally signed, then swap it with another one.
1 reply 0 retweets 0 likes -
but what would the differences be? Would they be *useful*?
1 reply 0 retweets 0 likes -
Replying to @andrewgdotcom @thegrugq
You can make the two documents look completely different. See https://alf.nu/SHA1 and my other tweets.
1 reply 1 retweet 0 likes -
aha, sorry I get it now. You add the same data to both files but in one case the first half of it is commented out.
1 reply 0 retweets 0 likes
Replying to @andrewgdotcom @thegrugq
Effectively, yes. This also works for executable files and many complex file formats.
4:24 AM - 26 Feb 2017
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.